Impact
A kernel bug causes a DIO reference to be left referenced when a metadata mapping error occurs. The retained reference prevents the underlying I/O buffer from being released, which can lead to reduced available memory, degraded performance, or a kernel panic if the leak accumulates. The impact is limited to denial of service and system instability; there is no evidence in the data that it grants code execution or privileges.
Affected Systems
All Linux distributions that use the Linux kernel without the recent patch are potentially affected. The vendor product list indicates the default Linux kernel; no specific version range is supplied, so any kernel build prior to the fix may still have the issue.
Risk and Exploitability
The EPSS score of less than 1% shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. An attacker would need to create or trigger metadata mapping errors, most likely through local privileged actions or by presenting malformed block device input. The low probability is offset by the high potential impact on availability if the leak is not addressed. The risk remains moderate, and the incident should be treated as a potential stabilization issue rather than a critical threat.
OpenCVE Enrichment